In this weekly review of data security incidents, you will find details on the alleged theft of identity cards data in Malaysia and an incident with the cloud storage provider in Hong Kong.
The first incident was a potential tremendous data leakage, which happened in Malaysia. The National Cyber Security Agency in Malaysia investigates rumors of alleged theft of MyKad (Malaysian identity card) data on 17 million Malaysians, while the National Registration Department (NRD) has denied allegations of data breach. Claims of a massive breach first appeared on X (formerly Twitter) on the 3rd of December. Initially, it was claimed that MyKad data was offered for sale online. Some samples of Malaysian ID cards were presented as proof of breach. MyKad contains such information as:
Aside from being an ID card, MyKad could also be used as a valid driver’s license, an ATM card, an electronic purse for digital cash, and a public key. Thereby, such information can be used for committing such crimes as identity theft, unauthorized access to financial accounts, and financial fraud.
This breach, if it had actually happened, could be one of the largest leaks of personal data in Malaysia. The National Cyber Security Agency will notify about any future updates regarding the alleged data breach. NACSA's spokesperson urged the public to “avoid spreading unconfirmed reports and only refer to verified information from the official authorities.”
The current incident is not the first case of data leaks among financial institutions in Malaysia. Earlier this year, in July, Malaysia’s largest bank, Maybank, also faced allegations about a potential data breach. Such incidents are highlighting the necessity for proper sensitive data protection and sufficient legislative standards for personal data processing and storage.
The second incident occurred in Hong Kong. According to the statement, dated 9th December, the Office of the Privacy Commissioner for Personal Data (PCPD) reported its investigation of a personal data breach. Moreover, PCPD states that government bodies failed to implement appropriate measures to protect the personal data of people who passed COVID-19 tests in 2022.
The watchdog had previously alerted officials that information about 17,000 persons is accessible online. According to the report, the problem was caused by a cloud platform called ArcGIS Online. The Electrical and Mechanical Services Department (EMSD) signed a deal with the mentioned service provider. According to the terms of the agreement, the cloud platform had to keep data about COVID-19 tests. EMSD wrongly assumed that personal data would be automatically erased after expiration of the contract by February 2023. In April 2024, EMSD discovered that testing data had not been deleted and still could have been accessed even without logging into the website.
According to the report, leaked data included:
This incident emphasizes the significance of risks related to the use of third-party services. Moreover, the proliferation of cloud services only accentuates the importance of ensuring appropriate and secure data storage, processing, and distribution in compliance with regulators demands.
To prevent such serious incidents, consider implementing managed security services. MSS is a smart and budget-friendly solution that ensures comprehensive protection. Click here and get your free 30-day trial to see if it is a fit for you.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!